CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38229
8.1 HIGH

.NET and Visual Studio Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-38212
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-38179
8.8 HIGH

Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-38149
7.5 HIGH

BranchCache Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-38129
7.5 HIGH

Windows Kerberos Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-38124
9.0 CRITICAL

Windows Netlogon Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-38097
7.1 HIGH

Azure Monitor Agent Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-38029
7.5 HIGH

Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-37983
6.7 MEDIUM

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-37982
6.7 MEDIUM

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-37979
6.7 MEDIUM

Windows Kernel Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-37976
6.7 MEDIUM

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-35215
6.2 MEDIUM

NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an …

Oct 8, 2024
CVE-2024-30092
8.0 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-25885
7.5 HIGH

An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a …

Oct 8, 2024
CVE-2024-20659
7.1 HIGH

Windows Hyper-V Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-9622
5.3 MEDIUM

A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an …

Oct 8, 2024
CVE-2024-9621
5.3 MEDIUM

A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to …

Oct 8, 2024
CVE-2024-9620
5.3 MEDIUM

A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could …

Oct 8, 2024
CVE-2024-9381
7.2 HIGH

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

Oct 8, 2024
CVE-2024-9380
7.2 HIGH KEV

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to …

Oct 8, 2024
CVE-2024-9379
6.5 MEDIUM KEV

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL …

Oct 8, 2024
CVE-2024-9167
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.

Oct 8, 2024
CVE-2024-9124
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavailable. The device may require …

Oct 8, 2024
CVE-2024-8626
7.5 HIGH

Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple …

Oct 8, 2024
CVE-2024-7612
8.8 HIGH

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

Oct 8, 2024
CVE-2024-47011
7.5 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information

Oct 8, 2024
CVE-2024-47010
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Oct 8, 2024
CVE-2024-47009
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Oct 8, 2024
CVE-2024-47008
7.5 HIGH

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

Oct 8, 2024
CVE-2024-47007
7.5 HIGH

A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.

Oct 8, 2024
CVE-2024-45918
9.8 CRITICAL

Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.

Oct 8, 2024
CVE-2024-44349
9.8 CRITICAL

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure …

Oct 8, 2024
CVE-2024-3057
9.8 CRITICAL

A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.

Oct 8, 2024
CVE-2024-8215
8.4 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This …

Oct 8, 2024
CVE-2024-47951
3.5 LOW

In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

Oct 8, 2024
CVE-2024-47950
3.5 LOW

In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

Oct 8, 2024
CVE-2024-47949
4.9 MEDIUM

In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

Oct 8, 2024
CVE-2024-47948
4.9 MEDIUM

In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

Oct 8, 2024
CVE-2024-47161
4.3 MEDIUM

In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

Oct 8, 2024
CVE-2024-45231
5.3 MEDIUM

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers …

Oct 8, 2024
CVE-2024-45230
7.5 HIGH

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to …

Oct 8, 2024
CVE-2024-45880
8.0 HIGH

A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the …

Oct 8, 2024
CVE-2024-45330
7.2 HIGH

A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted …

Oct 8, 2024
CVE-2024-33506
3.3 LOW

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote …

Oct 8, 2024
CVE-2024-8482
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and …

Oct 8, 2024
CVE-2024-8431
4.3 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Oct 8, 2024
CVE-2024-9207
6.1 MEDIUM

The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in …

Oct 8, 2024
CVE-2024-9005

CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to …

Oct 8, 2024
CVE-2024-8884
9.8 CRITICAL

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network …

Oct 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.